- Design, implement, and maintain SIEM solutions using Splunk Enterprise Security (ES) platform to monitor and analyze security event logs from various sources.
- Develop use cases for threat detection, correlation, and incident response to identify potential security threats in real-time.
- Collaborate with SOC teams to develop playbooks for automated incident response processes using Splunk's SOAR capabilities.
- Conduct regular health checks on the SIEM system to ensure optimal performance and accuracy of alerts.
Job Requirements :
- 7-13 years of experience in IT services & consulting industry with expertise in Splunk Enterprise Security (ES).
- Robust understanding of SPL language for writing custom scripts and use cases.
- Experience with SOAR tools such as Splunk's own SOAR module or third-party integrations like Demisto or Phantom.